Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

261–270 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#261
post #157

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

> It won't catch anything but the dumbest of dumb criminals Dumb is a pretty accurate description of a large fraction of criminals. For the most part you only get smart criminals when you are talking about crimes where you have to be smart to even plan and carry out the crime.

You only hear about the criminals who get caught and crimes that go unsolved get blamed on these kinds of criminals.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#262
post #89

Earlier quoted context omitted.

No. Most proper cryptographic hash systems (e.g. used for verifying files, rather than data structures) never have collisions. Try to find a SHA256 collision. Anywhere, ever, in the history of mankind. This isn't for lack of looking. A lot of very smart people have looked for them. If you find one, I bet you'll be eligible for a tenured faculty slot at a good university, if not more. A whole world of secure systems w…

Yes, but cryptographic hashes are irrelevant here because they'd allow to easily bypass CSAM by modifying/appending a single byte.

It's trivial to cause a neural hash non-match-- either imperceptibly with a little noise, or by adding an overlay on the image.

If you downsample and quantize an image before sha256ing it you get a bit of robustness to accidental false-negatives. While both schemes are trivially bypassable.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#263

Can this affect people who do not use Apple products?

As a non-apple user you could be impacted indirectly by people you know being directly impacted or by Apple's practices being imported into the law. E.g. laws that attempt to outlaw encryption lacking apple-like backdoors.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#264
post #225

Earlier quoted context omitted.

Given the average user don't know what a url is and a pedophile can use the darknet, I'd say criminals are not all dumb.

It is not so easily comparable. It’s all about your intrests and expectations. Darknet might sound bit complex, but as darknet user, you literally just install different browser.

Something like 40 percent of people use the default browser installed by the os.

We're just in an echo chamber of people who know what JavaScript is, and that distorts our perception of the world.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#266

Earlier quoted context omitted.

I don't really want my family photos reviewed by strangers. "Reducing the search space" of photos on my phone isn't an outcome I want to live with. At the time someone is looking at photos of my, my wife/husband/girlfriend/boyfriend, and my kids, they'd better have a darned good reason (e.g. a search warrant). I'd also appreciate if Apple let me know if my false positives were reviewed and found to not be CASM.

Don’t upload an image anywhere, else it can be reviewed.

I saw a story on here yesterday about iphones resetting to default settings after restarting. So people were turning off backups to the cloud, and then finding that their device turned the feature on after sometime.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#267
post #244
post #124

Earlier quoted context omitted.

Perceptual hashes are only used to reduce the search space for human review. Apple doesn’t have images in the CSAM database to do a comparison, but if it’s just a picture of a door their going to reject it. Also, because human review is an expense Apple’s incentives are to minimize the number of times it happens, thus the requirement for multiple collisions.

> Perceptual hashes are only used to reduce the search space for human review. False. The Apple proposed system leaks the cryptographic keys needed to decode the images conditional on the match (threshold of matches) of the faulty neuralhash perceptual hash. Matching these hashes results in otherwise encrypted highly confidential data being decodable by apple, accessable on their servers to the relevant staff along w…

Apple can decode the data either way. Their the ones doing the encryption on their servers.

There are two basic reasons for this first it’s a backup service which makes end to end encryption risky, but second they also let users share access to their baked up photos. iCloud > photos > shared album.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#268
post #225

Earlier quoted context omitted.

It is not so easily comparable. It’s all about your intrests and expectations. Darknet might sound bit complex, but as darknet user, you literally just install different browser.

Something like 40 percent of people use the default browser installed by the os. We're just in an echo chamber of people who know what JavaScript is, and that distorts our perception of the world.

Can you give source for that number? Regardless, browser is like any other app. If that amount of people don’t know how to install apps on their computers, then we have a either real dump people (or just lack of motivation) or great UX design failure in general.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#269
post #251

Earlier quoted context omitted.

I think before a criminal investigation, or any investigation at all is pursued, a human verifying the images would dismiss the false positive. I would think surreptitiously placing actual child porn on a rival's phone/computer would be much, much more effective. Cybercriminals could likely do all this remotely. Phish for apple account login, upload images. Done.

> a human verifying the images would dismiss the false positive How is a human supposed to distinguish that a visual derivative (a low res sobel filtered image, presumably) of ordinary, lawful, adult pornography isn't child porn when the system has already identified it as such? I agree that using real child porn is an attack too, but at least in that case you could say the system was doing as designed (even though w…

Are you saying humans cannot visually inspect the actual image that the flag is set against? If not, then how on earth do you prosecute someone if you can't demonstrate they had the actual image, and not just the derivation used to flag it?

The way I see it working is Apple scans a ton of shit, some of it shows up as possible child porn, human intervenes and looks at the source images, if there is indeed child porn they report to the police.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#270
post #248
post #233

Earlier quoted context omitted.

The government doesn’t supply the hashes in an unauditable way, that is a totally false statement. The hashes are supplied by NCMEC, a non-profit which is auditable, not a secret government agency. In any case, even if a non-CSAM hash were somehow in the database, Apple reviews the images before making reports, and those reports are used in normal criminal prosecutions.

Courts have determined that for this purpose the NCMEC is an agent of the government. NEMEC is 99% funded by the government and its ability to handle child porn is directly deprived from a explicit legislative carveout for them by name. What they do would be a felony for you or I to do. The fact that they are technically non-profit rather than an agency makes them significantly less accountable to the public. We cann…

> And we have no way to tell what their database contains, nor is there any avenue for redress should we somehow learn of an inappropriate listing.

Yes there is. It’s called legal liability. They are not immune to being held accountable for their actions just like any other non-profit. They may be immune from prosecution for possessing CSAM, but they don’t have any kind of immunity for damages they cause through their own actions.

Post reply on HN